NetSec_1_SecurityThreats Flashcards
Three Classifications of Network Attacks
- Recon
- Access
- Denial of Service (DoS)
Vulnerability
Weakness or flaw in the network.
Risk
Potential of a threat to exploit the vulnerabilities of an asset.
Mitigation
Action of reducting the severity of a vulnerability.
Threat
Potential for a vulnerability to turn into a network attack.
Attack Vector
Path or other means by which an attacker can gain access to a server, host, or network.
Vectors of Data Loss (6)
- Email/ Social Networking
- Unencrypted Devices
- Cloud Storage Devices
- Removable Media
- Hard Copy
- Improper Access Controls (Passwords, RFIDs, etc)
AAA Server Defined
Authentication, authorization, and accounting server.
VPN Defined
Virtual Private Network - Allows remote access, using a secured connection, to a system as if you were at the system.
ASA Defined
Adaptive Security Appliance - Firewall that performs stateful packet filtering into the network.
IPS Defined
Intrusion Protection System - Monitors incoming / outgoing network traffic for malicious activity.
ESA / WSA Defined
Email / Web Security Appliance
ISR Defined
Integrated Service Router - Router which can provide additional services aside from just routing.
CAN Defined
Campus Area Network - Network made up of an interconnection of LANs within a limited geographical area. ( Business site, college campus, factory location, etc)
Virtual Machine Specific Threats
- Hyperjacking
- Instant-On Activation
- Anti-Virus Storms